CVE-2024-27081

Source
https://cve.org/CVERecord?id=CVE-2024-27081
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27081.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-27081
Aliases
Published
2024-02-26T16:29:21.620Z
Modified
2026-04-10T05:12:02.820633Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ESPHome remote code execution via arbitrary file write
Details

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the configuration directory rendering remote code execution possible. This vulnerability is patched in 2024.2.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27081.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/esphome/esphome

Affected ranges

Type
GIT
Repo
https://github.com/esphome/esphome
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2021.*
2021.10.0
2021.10.0b1
2021.10.0b2
2021.10.1
2021.10.2
2021.10.3
2021.11.0
2021.11.1
2021.11.2
2021.11.3
2021.11.4
2021.12.0
2021.12.1
2021.12.2
2021.12.3
2021.8.0
2021.8.1
2021.8.2
2021.9.0
2021.9.1
2021.9.2
2021.9.3
2022.*
2022.1.0
2022.1.1
2022.1.2
2022.1.3
2022.1.4
2022.10.0
2022.10.1
2022.10.2
2022.11.0
2022.11.1
2022.11.2
2022.11.3
2022.11.4
2022.11.5
2022.12.0
2022.12.1
2022.12.2
2022.12.3
2022.12.4
2022.12.5
2022.12.6
2022.12.7
2022.12.8
2022.2.0
2022.2.1
2022.2.2
2022.2.3
2022.2.4
2022.2.5
2022.2.6
2022.3.0
2022.3.1
2022.3.2
2022.4.0
2022.5.0
2022.5.1
2022.6.0
2022.6.1
2022.6.2
2022.6.3
2022.8.0
2022.8.1
2022.8.2
2022.8.3
2022.9.0
2022.9.1
2022.9.2
2022.9.3
2022.9.4
2023.*
2023.10.0
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.11.0
2023.11.1
2023.11.2
2023.11.3
2023.11.4
2023.11.5
2023.11.6
2023.12.0
2023.12.1
2023.12.2
2023.12.3
2023.12.4
2023.12.5
2023.12.6
2023.12.7
2023.12.8
2023.12.9
2023.2.0
2023.2.1
2023.2.2
2023.2.3
2023.2.4
2023.3.0
2023.3.1
2023.3.2
2023.4.0
2023.4.1
2023.4.2
2023.4.3
2023.4.4
2023.5.0
2023.5.1
2023.5.2
2023.5.3
2023.5.4
2023.5.5
2023.6.0
2023.6.1
2023.6.2
2023.6.3
2023.6.4
2023.6.5
2023.7.0
2023.7.1
2023.8.0
2023.8.1
2023.8.2
2023.8.3
2023.9.0
2023.9.1
2023.9.2
2023.9.3
2024.*
2024.2.0
v1.*
v1.1
v1.12.0
v1.12.0b1
v1.12.0b2
v1.12.0b3
v1.12.0b4
v1.12.1
v1.12.2
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.16.0
v1.16.1
v1.16.2
v1.17.0
v1.17.1
v1.17.2
v1.18.0
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.2.1
v1.2.2
v1.20.0
v1.20.1
v1.20.2
v1.20.3
v1.20.4
v1.3.0
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.9.0b1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27081.json"